* fix(analytics): mask session replays by default, chrome-only unmask
Invert PostHog session-replay masking from visible-by-default with pattern
masking to deny-by-default: every input value is masked wholesale (rrweb
maskAllInputs, no maskInputFn) and every text node is masked unless it sits
under data-ph-unmask chrome or a table column header (th). Chrome tags live
on the shared UI primitives (PageHeader, Label, Button except combobox
triggers, TabsTrigger, Badge, Card/Dialog/Sheet titles, tooltips, help
popovers, empty states, settings labels), and tagged chrome is still
pattern-scrubbed for amounts and person-/organisationsnummer. data-ph-mask
beats data-ph-unmask, so call sites that interpolate user data into chrome
stay masked; a very-thorough audit swept every unmasked primitive and each
found site got a call-site mask. Confirm-dialog wrappers and toasts stay
masked centrally: their copy describes user objects by design. Untagged new
UI over-masks instead of leaking. Privacy policy, RoPA and decision log
updated in the same change.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(analytics): tag detail-section chrome merged from main
The register-detail primitives landed on main after the replay-masking
audit ran: kickers and DefRow labels are static i18n chrome, values stay
masked.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(analytics): close skeptic and review findings on replay masking
Explicit data-ph tags now resolve before the th chrome fallback, so a th
nested inside a data-ph-mask container masks correctly (regression test
added). Seven missed text-leak sites get call-site masks: delete-invoice
and credit-page invoice numbers, IB-correction voucher reference, TIC
orgnr (served unnormalized, so the separator-based scrub cannot be relied
on), articles search-term empty state, dimension segment labels, and
activate-account buttons. The attribute channel is closed with rrweb's
blockClass: inputs whose placeholder carries an effective user value
(salary overrides, correction description, danger-zone confirms, credit
confirm) get ph-no-capture, removing the element from recordings while
the prefill UX stays intact; the pivot-th title attribute is dropped.
Privacy-policy effective date bumped to 2026-08-17.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ui): shared migration primitives (UI migration PR 3)
The component kit every page migration (PR 4-8) builds on:
- ContextPicker: the one-per-page chip-dropdown context scope (convention
8), right-aligned popover with checks and muted annotations
- FyPicker: fiscal-year picker on ContextPicker with the same controlled
API and per-company localStorage key as FiscalYearSelector, which it
replaces page by page from PR 4
- SplitButton: primary + caret menu, last-used mode persisted per user
via ui_state.create_mode (lib/ui-state/client, unit-tested); nav
persistence refactored onto the same helper
- ConfirmDialog: centered min-460px confirm-up-front dialog (convention
10) with pending state on an awaitable onConfirm
- HelpPopover: 17px "?" after the H1 opening an anchored popover
(convention 7); PageHeader gets a `help` slot
- AttnLine: the one-ochre-sentence attention pattern (convention 6) with
optional inline action; new AA-safe --attn token pair
- RowStatus: chips-mark-exceptions helper (convention 5)
- SlideOver: right review panel, 480px, 18px inset, rounded, veil + Esc
(convention 13), with header kicker / body / footer slots
- Stagger: .stagger-enter applied to the five target pages' list
containers (bookkeeping, transactions, pending, invoices,
supplier-invoices); structural loading.tsx added for supplier-invoices,
customers, kpi, pending, deadlines
No page adopts the new pickers/dialogs yet: that is PR 4-8, one page per
PR against this kit.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(ui): FyPicker chip must not double the Rakenskapsar label
Real fiscal periods are often named "Rakenskapsar 2026" already; only
prefix the label when the period name lacks it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>